Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership
Festlandchina Wirtschaftsverkehr: Incident Response China Business. Geführter Spezialskill mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Manage incident response for Clerk authentication issues. Use when handling auth outages, security incidents, or production authentication problems.
Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment,
Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise,
Strukturierte Sofortmassnahmen bei aktivem Cyber-Vorfall — Hacker-Angriff Ransomware Datenexfiltration Insider-Threat. Phase 1 Sofort-Eindaemmung Netztrennung Forensik-Sicherung.
Run a structured response to a suspected web or server compromise. Follows SANS PICERL — Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned — and…
Guides teams through IT outages and security incidents, providing structured workflows for detection, containment, eradication, and post-mortem analysis.
Network forensics evidence collection and analysis during security incidents. Guides volatile evidence preservation, lateral movement detection via flow records and ARP/MAC/CAM…
Incident Response Planner - Auto-activating skill for Security Advanced. Triggers on: incident response planner, incident response planner Part of the Security Advanced skill…
Drafts incident response plans and scenario playbooks for U.S. legal organizations, aligning NIST SP 800-61 Rev.
Coordinate security incident response efforts. Includes classification, playbook generation, evidence gathering, and remediation planning.
Cybersecurity incident response expert (NIST SP 800-61r2, SANS, ISO 27035). Guides the full incident lifecycle: detection, triage, severity classification, containment, e — from…
Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy
Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation,
When to use: active or suspected Salesforce org compromise, unauthorized access investigation, attacker containment, forensic evidence collection from EventLogFile/LoginHistory,…
Plan de réponse aux incidents de sécurité — préparation, détection, containment, éradication, recovery et lessons learned.
Cybersecurity incident response expert (NIST SP 800-61r2, SANS, ISO 27035). Guides the full incident lifecycle: detection, triage, severity classification, containment, e — from…